nginx
tcp/443
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e0790782f9790782f9790782f9790782f9790782f97
Symfony profiler enabled: https://genesispromociones-generalion.chequemotivadev.com/_profiler/empty/search/results
Open service 13.48.179.245:443 · genesispromociones-generalion.chequemotivadev.com
2026-01-09 18:57
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=0, must-revalidate, private
Date: Fri, 09 Jan 2026 18:57:12 GMT
X-Debug-Token: 63df1d
X-Robots-Tag: noindex
Expires: Fri, 09 Jan 2026 18:57:12 GMT
Set-Cookie: PHPSESSID=ve17or455h75kkatsd83ebhaoi; expires=Sat, 10-Jan-2026 18:57:12 GMT; Max-Age=86400; path=/; secure; httponly; samesite=lax
Content-Security-Policy:
default-src 'self';
script-src 'self' https://cdn.datatables.net https://cdnjs.cloudflare.com https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://www.gstatic.com 'unsafe-inline';
style-src 'self' https://cdn.datatables.net https://cdnjs.cloudflare.com https://fonts.googleapis.com 'unsafe-inline';
font-src 'self' https://fonts.gstatic.com data:;
img-src 'self' data: https:;
connect-src 'self' https:;
frame-src 'self' https://www.google.com;
object-src 'none';
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer-when-downgrade
Permissions-Policy: geolocation=(self), microphone=()
Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 13.48.179.245:443 · genesispromociones-generalion.chequemotivadev.com
2025-12-23 04:06
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=0, must-revalidate, private
Date: Tue, 23 Dec 2025 04:06:42 GMT
X-Debug-Token: f53484
X-Robots-Tag: noindex
Expires: Tue, 23 Dec 2025 04:06:42 GMT
Set-Cookie: PHPSESSID=g6hk2np8l48nnbg570v8gorj1u; expires=Wed, 24-Dec-2025 04:06:42 GMT; Max-Age=86400; path=/; secure; httponly; samesite=lax
Content-Security-Policy:
default-src 'self';
script-src 'self' https://cdn.datatables.net https://cdnjs.cloudflare.com https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://www.gstatic.com 'unsafe-inline';
style-src 'self' https://cdn.datatables.net https://cdnjs.cloudflare.com https://fonts.googleapis.com 'unsafe-inline';
font-src 'self' https://fonts.gstatic.com data:;
img-src 'self' data: https:;
connect-src 'self' https:;
frame-src 'self' https://www.google.com;
object-src 'none';
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer-when-downgrade
Permissions-Policy: geolocation=(self), microphone=()
Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 13.48.179.245:443 · genesispromociones-generalion.chequemotivadev.com
2025-12-21 10:15
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=0, must-revalidate, private
Date: Sun, 21 Dec 2025 10:15:03 GMT
X-Debug-Token: 8be900
X-Robots-Tag: noindex
Expires: Sun, 21 Dec 2025 10:15:03 GMT
Set-Cookie: PHPSESSID=r8e8v5dv0bdfajh6sai1jkoogs; expires=Mon, 22-Dec-2025 10:15:03 GMT; Max-Age=86400; path=/; secure; httponly; samesite=lax
Content-Security-Policy:
default-src 'self';
script-src 'self' https://cdn.datatables.net https://cdnjs.cloudflare.com https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://www.gstatic.com 'unsafe-inline';
style-src 'self' https://cdn.datatables.net https://cdnjs.cloudflare.com https://fonts.googleapis.com 'unsafe-inline';
font-src 'self' https://fonts.gstatic.com data:;
img-src 'self' data: https:;
connect-src 'self' https:;
frame-src 'self' https://www.google.com;
object-src 'none';
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer-when-downgrade
Permissions-Policy: geolocation=(self), microphone=()
Strict-Transport-Security: max-age=31536000; includeSubDomains